prerequisites … 7-5

remove self-signed certificate … 7-9 remove server host certificate … 7-9 reserved TCP port numbers … 7-20 root … 7-4

root certificate … 7-4self-signed7-4,7-12

self-signed certificate … 7-4,7-9,7-12 server host certificate … 7-9

SSL server … 7-3 SSLv3 … 7-2 stacking, security … 7-6 steps for configuring … 7-5 supported encryption methods … 7-3 terminology … 7-3

TLSv1 … 7-2

troubleshooting, operating … 7-21 version … 7-2

zeroize … 7-10,7-11stacking

SSH security … 6-8 SSL security … 7-6

T

TACACS

aaaparameters … 4-12 authentication … 4-3 authentication process … 4-20 authentication, local … 4-22 authorized IP managers, effect … 4-25 authorized IP managers, precedence … 10-2 configuration, authentication … 4-11 configuration, encryption key … 4-19 configuration, server access … 4-15 configuration, timeout … 4-20 configuration, viewing … 4-10 encryption key … 4-6,4-15,4-16,4-19 encryption key, general operation … 4-23 encryption key, global … 4-20

general operation … 4-2 IP address, server … 4-15

local manager password requirement … 4-26 messages … 4-25

NAS … 4-3 overview … 1-2 precautions … 4-5 preparing to configure … 4-8

preventing switch lockout … 4-15 privilege level code … 4-7 server access … 4-15

server priority … 4-18 setup, general … 4-5 show authentication … 4-8 system requirements … 4-5 TACACS+ server … 4-3 testing … 4-5

timeout … 4-15 troubleshooting … 4-6 unauthorized access, preventing … 4-7 web access, controlling … 4-24

web access, no effect on … 4-5tacacs-server4-8

TCP

reserved port numbers … 7-20

TLS

See RADIUS. troubleshooting

authorized IP managers … 10-12trunk

LACP, 802.1X not allowed … 8-17 See also LACP.

U

user name cleared … 2-5

V

value, inconsistent … 9-15

VLAN

802.1X … 8-54

802.1X, ID changes … 8-57

802.1X, suspend untagged VLAN … 8-51 not advertised for GVRP … 8-57

W

warranty … 1-iiWeb Authentication

authenticator operation … 3-5 blocked traffic … 3-4

CHAP

defined … 3-9 usage … 3-4

6 – Index